Unrar Path Traversal Vulnerability affects Zimbra Mail
https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/
https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/
Sonarsource
Unrar Path Traversal Vulnerability affects Zimbra Mail
We discovered a vulnerability in Zimbra Enterprise Email that allows an unauthenticated, remote attacker fully take over Zimbra instances via a flaw in unrar.
👍1
Mez0: Vulpes: Obfuscating Memory Regions with Timers
https://mez0.cc/posts/vulpes-obfuscating-memory-regions/
https://mez0.cc/posts/vulpes-obfuscating-memory-regions/
Game Of Active Directory v2 | Mayfly
https://mayfly277.github.io/posts/GOADv2/
https://mayfly277.github.io/posts/GOADv2/
Mayfly
Game Of Active Directory v2
Yes another pentester blog..
GitHub - winterknife/PINKPANTHER: Windows x64 handcrafted token stealing kernel-mode shellcode
https://github.com/winterknife/PINKPANTHER
https://github.com/winterknife/PINKPANTHER
GitHub
GitHub - winterknife/PINKPANTHER: Windows x64 handcrafted token stealing kernel-mode shellcode
Windows x64 handcrafted token stealing kernel-mode shellcode - winterknife/PINKPANTHER
Brute Ratel C4 Red Teaming Tool Being Abused by Malicious Actors
https://unit42.paloaltonetworks.com/brute-ratel-c4-tool/
https://unit42.paloaltonetworks.com/brute-ratel-c4-tool/
Unit 42
When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors
Pentest and adversary emulation tool Brute Ratel C4 is effective at defeating modern detection capabilities – and malicious actors have begun to adopt it.
VOD will be up later, but the commands for a layer2 tunnel were:
sudo ssh -o Tunnel=ethernet -w 0:0 root@172.16.204.130
ip link add br0 type bridge
ip link set ens160 master br0
ip link set tap0 master br0
ip link set tap0 up (run on both ends)
ip link set br0 up
sudo ssh -o Tunnel=ethernet -w 0:0 root@172.16.204.130
ip link add br0 type bridge
ip link set ens160 master br0
ip link set tap0 master br0
ip link set tap0 up (run on both ends)
ip link set br0 up
AMSI Bypass - Memory Patching - aidenpearce369
https://aidenpearce369.github.io/offsec/AMSI-Memory-Bypass/
https://aidenpearce369.github.io/offsec/AMSI-Memory-Bypass/
GitHub - edoardottt/awesome-hacker-search-engines: A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red Team operations, Bug Bounty and more
https://github.com/edoardottt/awesome-hacker-search-engines
https://github.com/edoardottt/awesome-hacker-search-engines
GitHub
GitHub - edoardottt/awesome-hacker-search-engines: A curated list of awesome search engines useful during Penetration testing,…
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more - edoardottt/awesome-hacker-search-engines